Every topic through three lenses: policy, process, technical. Pick a family, then click any control to light up its mappings.
432 controls · 20 families · 2214 mapped pairs
Frameworks
Family
Lens
Sekit CSF · Supply Chain Security
ISO/IEC 27001:2022
Sekit CSF · Supply Chain Security · Process
RCF-0317Vendor due diligence
Security assessments are consistently conducted at onboarding and reviewed periodically throughout the relationship
ISO/IEC 27001:2022
Running the security assessment at onboarding and repeating it on a cycle is what makes A.5.19's risk requirement operate rather than sit as a policy line.
Repeating the supplier security assessment on a defined cycle during the relationship is A.5.22's review requirement applied to security posture rather than availability.